Msrc Qemu-Img-4.2.0-29.Cm1.X86 64.Rpm On Cbl Mariner 1.0 X64 vulnerabilities
3 known vulnerabilities affecting msrc/qemu-img-4.2.0-29.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2LOW1
Vulnerabilities
Page 1 of 1
CVE-2021-3409MEDIUMCVSS 5.72021-03-09
CVE-2021-3409 [MEDIUM] CWE-119 The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation cod
The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation code. This flaw allows a malicious privileged guest to crash the QEMU p
msrc
CVE-2021-3416MEDIUMCVSS 6.02021-03-09
CVE-2021-3416 [MEDIUM] CWE-835 A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 5.2.0. The issue occurs in loopback mode of a NIC wherein reentrant DMA ch
A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 5.2.0. The issue occurs in loopback mode of a NIC wherein reentrant DMA checks get bypassed. A guest user/process may use this flaw to consume
msrc
CVE-2021-3392LOWCVSS 3.22021-03-09
CVE-2021-3392 [LOW] CWE-416 A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsas_free_request() that does not dequeue the request o
A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsas_free_request() that does not dequeue the request object 'req' from a pending requests queue. This flaw allows a privilege
msrc